Skip to content
Topic Contested in court

Integrity and Confidentiality Principle

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

While security and beveiliging topics exist, there is no dedicated topic for the integrity and confidentiality principle specifically as articulated in GDPR Article 5(1)(f), which is a distinct foundational principle requiring separate coverage.

330 linked items 2 Laws67 Case Law37 Guidance160 Enforcement37 News

Overview

23 sources · Jul 23, 2026

Legal Framework

Article 5(1)(f) GDPR establishes the integrity and confidentiality principle, requiring controllers to process personal data in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage. This principle is operationalized primarily through Article 32 GDPR, which mandates appropriate technical and organizational measures, and Article 28 GDPR, which extends these obligations to processor relationships.

The principle is broader than mere "security" in the technical sense. Recital 75 makes clear that the risk to rights and freedoms encompasses physical, material, and non-material damage — including identity theft, fraud, financial loss, reputational damage, loss of confidentiality of professionally protected data, and unauthorized reversal of pseudonymisation. Recital 85 reinforces that personal data breaches, if not addressed appropriately and timely, can produce precisely these harms. The doctrinal commentary underscores that the scope of required guarantees extends to expertise, reliability, and resources of processors — a wider standard than existed under the 1995 Data Protection Directive, which spoke narrowly of security measures.

Article 28(1) GDPR obligates controllers to engage only processors offering sufficient guarantees regarding appropriate technical and organizational measures. Article 28(3) prescribes in considerable detail what must be contractually binding between controller and processor — a marked expansion from the Directive era.

Key Developments

Enforcement practice confirms that controllers bear full risk when they cannot identify the source of unauthorized access. In the Beekdaelen case, the court held that the municipality's inability to identify who consulted a data subject's personal data, and for what purpose, was a circumstance falling entirely at the controller's risk. Absent a lawful basis for the processing, the court presumed unlawful processing — a demanding standard for organizations with inadequate access logging.

The Dutch DPA (AP) has actively enforced against unlawful processing, including imposing administrative fines and penalty payments on controllers who failed to cease unauthorized livestreaming of personal data. The AP confirmed that administrative fines can be imposed on public authorities for data breaches, signaling that no sector receives preferential treatment.

At the EU level, the CJEU in Weltimmo confirmed that national DPAs may hear claims from data subjects who consider themselves victims of unlawful processing, even where establishment questions remain unresolved. The Dennekamp ruling established that data protection rights and access-to-document rights must both be fully applied without one enjoying primacy over the other — relevant where confidentiality obligations intersect with transparency duties.

The Spanish DPA's enforcement against ENDESA (€60,000 fine) and Free Technologies Excom (€10,000 fine) illustrates that inadequate password management and insufficient verification of processing purposes constitute direct violations of the integrity and confidentiality principle.

Practical Guidance

  • Implement comprehensive access logging and monitoring: The Beekdaelen ruling makes clear that inability to identify who accessed personal data and why shifts the burden of proof to the controller. Maintain audit trails sufficient to demonstrate lawful processing of every access event.

  • Conduct processor due diligence on expertise, reliability, and resources: Article 28(1) requires more than contractual representations — assess the processor's actual operational capacity, security certifications, and organizational stability before engaging them.

  • Execute Article 28(3) processor agreements with full mandatory content: The contractual regime is prescriptive; ensure every required element — subject matter, duration, nature and purpose of processing, type of data, categories of data subjects, and technical/organizational measures — is explicitly addressed.

  • Map confidentiality obligations against transparency duties: Where sectoral professional secrecy or access-to-information regimes apply, document the balancing analysis to demonstrate full application of both legal frameworks, as required under Dennekamp.

  • Establish breach response procedures calibrated to Recital 85 harm categories: Assessment of breach severity must account for the full spectrum of potential damages — not just technical compromise but identity theft, financial loss, reputational harm, and reversal of pseudonymisation.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 2
rec 75 Recital 75 — personal data processing risks to individuals GDPR Apr 2016 rec 85 Recital 85 — personal data breach notification requirements GDPR Apr 2016
Case Law 67
¶10 Article 23 of that directive states: ‘1. Member States shall provide that any person who has suffered damage as a result of an unlawful processing ope… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶8 Article 5 of the GDPR, entitled ‘Principles relating to processing of personal data’, states: ‘1. Personal data shall be: (a) processed lawfully, fair… Judgment of the Court (First Chamber) of 30 March 2023.#Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium v Minister des Hessischen Kultusministeriums.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing of data in the employment context – Regional school system – Teaching by videoconference due to the COVID-19 pandemic – ¶2 The request has been made in proceedings between a natural person, X, on the one hand, and Russmedia Digital SRL and Inform Media Press SRL (together,… Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – ¶13 Article 5 of that regulation, entitled ‘Principles relating to processing of personal data’, provides: ‘1. Personal data shall be: (a) processed lawfu… Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 667/21 Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal Court of Justice of the European Union Dec 2023 33/22 Judgment of the Court (Grand Chamber) of 16 January 2024.#Österreichische Datenschutzbehörde v WK.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Article 16 TFEU – Regulation (EU) 2016/679 – Article 2(2)(a) – Scope – Exclusions – Activities which fall outside the scope of Union law – Article 4(2) TEU – Activities concerning national security – Committee of inquir Court of Justice of the European Union Jan 2024 65/23 Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6 Court of Justice of the European Union Dec 2024 340/21 VB v Natsionalna agentsia za prihodite CJEU Dec 2023 507/23 Judgment of the Court (Eighth Chamber) of 4 October 2024.#A v Patērētāju tiesību aizsardzības centrs.#Request for a preliminary ruling from the Augstākā tiesa (Senāts).#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 82(1) – Right to compensation and liability – Unlawful processing of data – Infringement of the right to protection of personal data – Concept of ‘damage’ – Compensation for non-material damage in the form of apologies – Whether Court of Justice of the European Union Oct 2024 473/12 Judgment of the Court (Third Chamber), 7 November 2013.#Institut professionnel des agents immobiliers (IPI) v Geoffrey Englebert and Others.#Request for a preliminary ruling from the Cour constitutionnelle (Belgium).#Processing of personal data — Directive 95/46/EC — Articles 10 and 11 — Obligation to inform — Article 13(1)(d) and (g) — Exceptions — Scope of exceptions — Private detectives acting for the supervisory body of a regulated profession — Directive 2002/58/EC — Article 15(1).#Case C‑47 Court of Justice of the European Union Nov 2013 655/23 Judgment of the Court (Fourth Chamber) of 4 September 2025.#IP v Quirin Privatbank AG.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Rights of the data subject – Article 17 – Right to erasure of data – Article 18 – Right to restriction of processing – Article 79 – Right to an effective judicial remedy – Unlawful processing of personal data Court of Justice of the European Union Sep 2025 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 638/23 Judgment of the Court (Eighth Chamber) of 27 February 2025.#Amt der Tiroler Landesregierung v Datenschutzbehörde.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Direct designation of the controller by national law – Auxiliary administrative entity in the service of a regional government – Lack of Court of Justice of the European Union Feb 2025 446/21 Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos Court of Justice of the European Union Oct 2024 740/22 Judgment of the Court (Sixth Chamber) of 7 March 2024.#Endemol Shine Finland Oy.#Request for a preliminary ruling from the Itä-Suomen hovioikeus.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Articles 2, 4, 6, 10 and 86 – Data held by a court relating to the criminal convictions of a natural person – Oral disclosure of such data to a commercial company on account of a competition organised by that company – Concept of ‘processing of personal data’ Court of Justice of the European Union Mar 2024 231/22 Judgment of the Court (Third Chamber) of 11 January 2024.#État belge v Autorité de protection des données.#Request for a preliminary ruling from the cour d'appel de Bruxelles.#Reference for a preliminary ruling – Approximation of laws – Protection of natural persons with regard to the processing of personal data and free movement of such data (General Data Protection Regulation) – Regulation (EU) 2016/679 – Point 7 of Article 4 – Concept of ‘controller’ – Official journal of a Member State – Obl Court of Justice of the European Union Jan 2024 200/23 Judgment of the Court (First Chamber) of 4 October 2024.#Agentsia po vpisvaniyata v OL.#Request for a preliminary ruling from the Varhoven administrativen sad.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Publication in the commercial register of a company’s constitutive instrument containing personal data – Directive (EU) 2017/1132 – Non-compulsory personal data – Lack of consent of the data subjec Court of Justice of the European Union Oct 2024 252/21 Meta Platforms v noyb CJEU Jan 2023 673/17 Bundesverband der Verbraucherzentralen v Planet49 GmbH CJEU Oct 2019 553/23 Judgment of the General Court (Tenth Chamber, Extended Composition) of 3 September 2025.#Philippe Latombe v European Commission.#Transfer of personal data to the United States – Commission Implementing Decision on the adequate level of protection of personal data ensured by the United States – Right to an effective remedy – Right to private and family life – Decisions based solely on the automated processing of personal data – Security of the processing of personal data.#Case T-553/23. General Court Sep 2025 162/22 Judgment of the Court (First Chamber) of 7 September 2023.#A. G. v Lietuvos Respublikos generalinė prokuratūra.#Request for a preliminary ruling from the Lietuvos vyriausiasis administracinis teismas.#Reference for a preliminary ruling – Telecommunications – Processing of personal data in the electronic communications sector – Directive 2002/58/EC – Scope – Article 15(1) – Data retained by providers of electronic communications services and made available to authorities in charge of criminal pro Court of Justice of the European Union Sep 2023 300/21 UI v Österreichische Post AG CJEU May 2023 483/13 Judgment of the General Court (Fourth Chamber) of 20 July 2016 (Extracts).#Athanassios Oikonomopoulos v European Commission.#Non-contractual liability — Damage caused by the Commission in the context of an OLAF investigation and by OLAF — Actions for damages — Action for a declaration that certain measures taken by OLAF were void and inadmissible for evidentiary purposes before the national authorities — Admissibility — Misuse of powers — Processing of personal data — Rights of the defence.#Case General Court Jul 2016 Show 47 more →
Guidance 37
guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines on technical scope of art 53 of eprivacy directive Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive EDPB Oct 2024 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on deceptive design patterns in social media platform interfaces how to recognise Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them EDPB Feb 2023 guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 guidelines on the interplay of the second payment services directive and the gdpr Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR EDPB Dec 2020 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on the criteria of the right to be forgotten in the search engines cases under th Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) EDPB Jul 2020 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 022021 on the legal basis for the storage of credit card Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions EDPB May 2021 guidelines on the application of article 651a gdpr Guidelines 03/2021 on the application of Article 65(1)(a) GDPR EDPB May 2023 guidelines on the practical implementation of amicable settlements Guidelines 06/2022 on the practical implementation of amicable settlements EDPB May 2022 Show 17 more →
Enforcement 160
AEPD (Spain) AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data AEPD (Spain) Jul 2026 APDCAT (Catalonia) APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender APDCAT (Catalonia) Jul 2026 ANSPDCP (Romania) ANSPDCP (Romania) - Fine against Homelux SRL ANSPDCP (Romania) Aug 2026 AEPD (Spain) AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator AEPD (Spain) Jul 2026 ANSPDCP (Romania) ANSPDCP fines Banca Transilvania RON 26,172 for inadequate security over unauthorized ANSPDCP (Romania) Jul 2026 ANSPDCP (Romania) ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026 ANSPDCP (Romania) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: Employer's recording of locker opening and destruction of contents Garante per la protezione dei dati personali (Italy) Jun 2026 Garante per la protezione dei dati personali (Italy) Italian DPA finds GDPR applies to US-based Character.AI service Garante per la protezione dei dati personali (Italy) Jul 2026 VDAI (Lithuania) VDAI (Lithuania) - 3R-1143 VDAI (Lithuania) Jun 2026 UODO (Poland) UODO (Poland) - DKN.5131.34.2023 UODO (Poland) Jun 2026 IP (Slovenia) Slovenian DPA fines controller €1,198 for Art. 32 GDPR breach via pirated software IP (Slovenia) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray Garante per la protezione dei dati personali (Italy) May 2026 UODO (Poland) UODO (Poland) - DKN.5131.5.2025 UODO (Poland) May 2026 UODO (Poland) UODO (Poland) - DKN.5131.27.2023 UODO (Poland) May 2026 UODO (Poland) UODO (Poland) - DKN.5131.7.2022 UODO (Poland) Apr 2026 Data Protection Authority of Ireland Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland May 2026 Persónuvernd (Island) Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive Persónuvernd (Island) Jul 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 HDPA (Greece) HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers HDPA (Greece) Jun 2026 AEPD (Spain) AEPD (Spain) - EXP202306354 (PS/00312/2024) AEPD (Spain) Feb 2026 Show 140 more →
News 37
GDPRhub ICO (UK) - ACRO Criminal Records Office GDPRhub Aug 2026 GDPRhub ANSPDCP (Romania) - AMATO BESTSELLER S.R.L. GDPRhub Aug 2026 European Digital Rights Information Integrity & Wikipedia: How community-governed platforms can inform future policy-making. European Digital Rights Feb 2026 European Digital Rights How recommender algorithms threaten election integrity European Digital Rights Feb 2026 GDPRhub DSB (Austria) - 2025-0.276.820 GDPRhub Jan 2026 GDPRhub DSB (Austria) - 2025-0.276.820 GDPRhub Jan 2026 European Digital Rights Why the Digital Omnibus puts GDPR and ePrivacy at risk European Digital Rights Nov 2025 Access Now Artificial Insecurity: how AI tools compromise confidentiality Access Now Feb 2026 European Digital Rights Why the "Digital Omnibus" threatens privacy regulations (GDPR and ePrivacy). European Digital Rights Nov 2025 GDPRhub ΔΔΚ - 1181/18 GDPRhub Jan 2026 Access Now Artificial Insecurity: threats to information integrity Access Now Feb 2026 European Digital Rights Why the "Digital Omnibus" endangers privacy rules (GDPR and ePrivacy). European Digital Rights Nov 2025 European Digital Rights e-Society.mk 2025: Integrity as the core of digital transformation. European Digital Rights Nov 2025 European Digital Rights e-Society.mk 2025: Integrity as the core of the digital transformation. European Digital Rights Nov 2025 European Digital Rights e-Society.mk 2025: Integrity at the core of digital transformation European Digital Rights Nov 2025 Government Three recommendations from the AP (Autoriteit Persoonsgegevens - Dutch Data Protection Authority) compiled together. Government Mar 2025 Government "This is the second part of a report on the implementation and use of the Risk Analysis Model (RAM) within the Dutch Tax Authority, the Benefits Agency, and Customs. The report examines, among other things, any potential negative consequences for citizens and businesses..." Government Mar 2025 Legislation Amendment of the Law on DNA testing for convicted individuals and the Code of Criminal Procedure, concerning the introduction of precautionary collection of cell samples and several other amendments related to DNA testing. Legislation Jun 2025 Government "2e deel van het rapport over de inrichting en het gebruik van het Risico Analyse Model (RAM) binnen de Belastingdienst, Dienst Toeslagen en de Douane. Het rapport kijkt daarbij onder andere naar eventuele nadelige gevolgen voor burgers en bedrijven do... Government Mar 2025 NL Government "This report examines the design and use of the Risk Analysis Model (RAM) within the Tax and Customs Administration, the Benefits Service and Customs. In doing so, the report looks, among other things, at any adverse consequences for citizens and businesses caused by unr... Government Mar 2025 Show 17 more →
Literature 27
European Journal of Risk Regulation The Court of Justice on the Excessiveness of Access Requests under the GDPR European Journal of Risk Regulation Jul 2026 Unio - EU Law Journal Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU Unio - EU Law Journal Jun 2025 European Data Protection Law Review All Talk, No Action? The Effect of the GDPR Accountability Principle on the EU Data Protection Paradigm European Data Protection Law Review Jan 2022 European Data Protection Law Review Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit? European Data Protection Law Review Jan 2022 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 Innovative STEM Education GDPR - General Data Protection Regulation on Sites Requiring Accessibility Innovative STEM Education Jun 2021 European Data Protection Law Review GDPR Implementation Series ∙ Latvia: The Implementation of the GDPR in a New Legislative Framework European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Finland: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Italy: The Legislative Procedure for National Harmonisation with the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ France: The French Approach to the GDPR Implementation European Data Protection Law Review Jan 2018 Show 7 more →